Cisco CCNP Security Core (SCOR) 350-701Cloud SecurityMedium

A company uses a public cloud provider for its infrastructure. The security team needs to ensure that all administrative access to cloud resources is logged, and that these logs are immutable and can be used for auditing and forensic investigations. Which cloud service or feature is primarily responsible for recording API calls and configuration changes made to cloud resources?

  1. ACloudWatch Logs
  2. BCloudTrail
  3. CAWS Config
  4. DAmazon GuardDuty
Show answer & explanation

Correct answer: B. CloudTrail

CloudTrail is specifically designed to record API calls and configuration changes made to AWS resources, providing a complete audit trail of actions taken by users, roles, or AWS services. These logs are crucial for security analysis, change tracking, and compliance auditing.

Why the other options are wrong

  • A. CloudWatch Logs collects and monitors logs from various AWS services and applications, but CloudTrail is the specific service for API call logging.
  • C. AWS Config records configuration changes to resources and evaluates them against desired configurations, but CloudTrail records the *actions* that *cause* those changes.
  • D. Amazon GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior, but it relies on CloudTrail and other logs as input, rather than being the primary logger of API calls itself.

CloudTrail (AWS)

An AWS service that records API calls made within an AWS account, providing an audit trail of actions.

  • Logs all API calls for auditing and compliance.
  • Tracks actions by users, roles, and services.
  • Helps with security analysis and troubleshooting.

Memory trick: CloudTrail: Tracks every Trail of activity.

More Cloud Security questions